Last updated: October 5, 2026
CB Guide is a local visitor and resident guide for Colonial Beach, Virginia, available at colonialbeachapp.com and as a mobile app. It is run by Charm City Sanctuary, LLC. Visitors do not need an account, and the app is built to work without collecting personal information. This page explains what information the app handles and why.
We use Umami, a cookie-free analytics tool, to count page views, app installs and app actions (such as opening the chat or tapping a button in a house guide) in aggregate. Inside a house guide, these counts include which house it is and a short topic label (for example "wifi"), never the words you typed. Umami does not use cookies and does not identify you.
When something breaks, the app sends a technical error report to Sentry so we can fix it. A report describes the error, the page, the technical steps just before it, and the browser and device type. Like any web request, it also reaches Sentry with your device's network address.
The map's "show my location" feature and the Then & Now photo feature can ask your device for your location, only when you use them. Your location is used on your device to show where you are. It is not sent to us or stored by us. Map images load from OpenStreetMap's servers, which see the part of the map being shown. You can decline location access, and the rest of the app works normally.
The bird identifier and the Then & Now feature can use your camera or a photo you pick. The image is processed on your device and is not uploaded to us or anyone else. In a house guide, an issue report can add a photo to a message you send your host yourself through your phone's share sheet; the app does not upload it. The bird identifier may download its recognition files from Google and jsDelivr, and it looks up the bird's name on Wikipedia.
Many of Skipper's answers come straight from the app on your phone. When Skipper needs to go online, your question and the last few messages of the conversation go to our server and to our AI provider, OpenAI, together with the house guide details the host approved. Before earlier messages are sent, email addresses and phone numbers are removed, and house answers Skipper gave from your phone are replaced with short notes. We turn off OpenAI's response storage for these requests; OpenAI's own API policies govern how it processes them.
Questions are not linked to your identity, our server does not keep a record of them, and they are not used for advertising or profiling. Conversations are not saved on your device either. Please don't type personal or sensitive information into the chat.
So its suggestions fit your stay, Skipper can keep a few short notes in a house guide: foods or activities you like or avoid, how many more nights you are staying, who is with you (for example "two kids"), and places it has already suggested. Skipper is told to note only what you tell it, and the app is built to keep out names, contact details, codes and health details. The notes are stored only on your phone and are sent with your questions to our server and OpenAI so the answers fit. Our server does not keep them, and they are never shown to other guests or to the host.
The app shows "Remembering for this stay" while notes exist, with a Forget button. Notes are erased when you tap Forget, after 36 hours without use, after 10 days at most, at checkout time on your leaving day, when the house code is entered again, when access to the guide ends, and when the guide is closed and locked. Expired notes are removed the next time the app checks them.
In a house guide, you can ask Skipper out loud with the microphone button. Your browser's or phone's own speech recognition turns your voice into text. Depending on your device, that may send the audio to the browser or phone maker (such as Google or Apple) under its own privacy policy. The app receives only the text, which is handled like a typed question. Spoken answers are read aloud by your device or browser; some browser voices are online services run by the browser maker.
The Stay Planner builds a plan for your stay on your phone, and the plan stays there. If you ask it to refine the plan online, only the options you picked (number of days, type of group, pace, budget, needs such as less walking, interests and whether to plan for rain) and which house it is go to our server and OpenAI, together with the house guide details the host approved. No names, dates or itinerary are sent.
If you submit an event, we receive the event details plus any contact name, email or phone number you choose to add. We store them in our database, email them to our team through our email provider, and use them only to review and publish the event and to contact you about it.
Alerts are off unless you turn them on in the Events tab. If you do, your browser gives us a notification address (a long random web address run by Google, Apple, Mozilla or Microsoft), and we store it with the event types you picked. We use it only to send at most one note a week about that weekend's events. Turning alerts off in the app deletes it, and addresses that stop working are deleted automatically. The address does not include your name, phone number or location.
Hosts who set up a house guide give us their name and email address, plus the details and photos they choose to share about their rental, such as the address and map location, house rules, Wi-Fi details, a phone number for guests, and answers to guest questions. If a host gives us a link to their public Airbnb, Vrbo or other rental listing, our server reads that public page to fill in the form. Photos in a guide are stored at public web addresses so the guide can show them. The house code is stored only in scrambled (hashed) form, plus an encrypted copy so the host can recover it.
An optional setup assistant helps hosts fill in the form. It sends the host's messages and the draft, which can include the host's name and the house address, to OpenAI. It is built to hold back messages that look like they contain a password, door or alarm code, email address or phone number; please put those details only in their own fields.
We store host information in our database to build and run the guide, and send related emails (sign-in codes, welcome and update emails, checkout notices) through our email provider. Hosts can update their guide at any time. To change the account email or have host information deleted, email us at the address below.
Hosts sign in with a 6-digit code we email them. We never store the code. Signing in sets cookies that keep the host signed in on that device for up to 90 days, and links in host emails work for up to a year. To slow down misuse, we count sign-in attempts against a scrambled (hashed) form of the email address.
When a host subscribes to keep their house guides switched on, payment is handled by Stripe on Stripe's own checkout pages. We never see or store card numbers. We send Stripe the host's email address, an internal account label (which may be based on the host's name), the town and the number of houses. We store the Stripe customer and subscription IDs, the subscription status and trial end date, and the email addresses allowed to switch the guides on. Stripe's privacy policy covers the information Stripe collects.
Guests open a private house guide with the house code their host provides. A single essential cookie keeps the guide unlocked on that device for up to 7 days; we store only a scrambled (hashed) version of that session. If a guest looks for something the host hasn't answered yet, we record the house and the topic with that scrambled session so the host can add the answer. When a guest confirms checkout, the host is notified that the group has left; no guest personal details are included.
If a host sends you a personal stay link, a second cookie remembers your stay dates until two days after checkout. We count guide use anonymously on our server, without IP addresses, browser details or cookies.
Some guides link to partner services, such as a complimentary song from VidaCanto. When you open one from a stay link, the partner receives a short-lived signed note with the house, the town, a stay reference number and your stay dates, but no name. Those services have their own privacy policies.
To stop repeated or automated misuse (for example, guessing house codes), our server turns your network address into a one-way scrambled value and counts requests against it. Host sign-in and sign-up count email addresses the same way. The address itself is held in server memory for up to an hour and is not stored.
Other AI assistants can connect to the app to look up public information: events, local businesses and places, weather and tides, and the public profiles of rentals whose hosts chose to be listed. Those requests contain only the assistant's search terms, such as dates, the number of guests or whether pets are coming. We do not receive your conversation with the assistant, and the assistant's own privacy policy governs that conversation.
We rely on a small number of providers to run the app: Vercel (hosting), Supabase (database and photo storage), Resend (email), OpenAI (Skipper and other AI features), Stripe (host payments), Umami (analytics) and Sentry (error reports). Like most web services, our hosting provider keeps short-lived technical logs to operate and secure the service.
Some screens load content directly from other services:
Google Maps opens only when you tap a directions link. These services see your device's network address when they load, and their own privacy policies apply.
The app keeps some things on your device so it works the way you left it:
This data stays on your device unless you send it, and clearing this site's data in your browser removes it.
We keep host, payment and event-submission records, stay-link records, checkout confirmations and records of unanswered guest questions while they are needed to run the app. Guide sessions stop working after 7 days, and alert addresses are deleted when you turn alerts off. To have your information deleted, email us at the address below.
The app is not directed at children and does not knowingly collect personal information from anyone under 13.
If our practices change, we will update this page and the date above.
Questions or deletion requests: colonialbeachapp@gmail.com